PoC Index

CVE-2018-1099

MEDIUM 5.5EPSS 0.5%

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS v3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS
0.50% chance of exploitation in the next 30 days, 41th percentile
Published
2018-04-03
Updated
2024-09-17

Proof-of-concept exploits (1)

References

Related